Privacy Impact Score is a score reflecting overall cookie-related impact of
the website relative to other websites, primarily taking into account the number of third-party domains
it reports to and number of persistent cookies it sets. See
Privacy Impact Score
article for more details.

Third-party domains

0

Persistent cookies

1

Session cookies

0

Third-party domains is the count of organisations allowed by the webmaster to trace
your across the site. These cookies may be set for various purposes, like tracking ads displayed on the
website, collection of statistics, targeted advertising etc. This website
allows 0
other websites to track your activity.

Persistent cookies are the cookies that are preserved through browser shutdowns. This
means, even if you close this page today and ever return there in future, the website will know you're
a returning visitor. This may be used for "remember me" features, as well as persistent user tracking.
These cookies, especially if set by third party organisations, are powerful tool for monitoring your
activities across all the websites you visit. This website sets 1
persistent cookies with average life-time of 90
days and longest 90 days.

Session cookies are cleared when you close your browser and allow the website to
identify user's state — such as logged-in users. They are mostly considered harmless because
they cannot be used for long-term user tracking. This site sets 0 session
cookies.

Cookies and Privacy Attributes

Secure The cookie sets the Secure flag but is itself set on a non-TLS (plaintext
HTTP) website. New browsers will ignore such cookies under the Strict
Secure cookie policy

sameSite This flag prevents the cookie from being automatically sent by browser
at specific cross-site requests, protecting from a range of attacks against authentication
and authorization (for example CSRF)
» More...

httpOnly This cookie is not readable by client-side JavaScript code
» More...

Cookies set with the new __Host- prefix are guaranteed to be set with
the Secure flag as well as have Path=/ and no Domain attribute
by compliant browsers (per draft-ietf-httpbis-rfc6265bis-02)

No base-uri allows attackers to inject base tags which override the base URI to an attacker-controlled origin. Set to 'none' unless you need to handle tricky relative URLs scheme

Consider adding block-all-mixed-content directive if your website is only accessible over TLS and you are certain it doesn not have any legacy plaintext resources. Otherwise you may add adding upgrade-insecure-requests directive if your website may still have some legacy plaintext HTTP resources and you want them to be still available rather than blocked

Sub-resources

Sub-resources

Most web pages load a number of sub-resources such as images, style sheets
(CSS),
JavaScript files, web fonts, audio or video files and other web pages in frames. Each of these
sub-resources
may be loaded from the same server (first-party resource) or servers belonging to other parties
(third-party resources).
In the latter case, the third-party will see a request coming from your browser with the
information
on
the originating page and it can set its own cookies, both of which are frequently used for user
tracking.
Note that the cookies set by these sub-resources are already recorded in our cookie statistics
for
this page.

The page loads 0 third-party JavaScript files and 5 CSS but does not employ Sub-Resource Integrity to prevent breach if a third-party CDN is compromised

Symbols

Resource
securely loaded over TLS

Resource
insecurely loaded over plaintext HTTP.

A third-party
resource. It may perform its own tracking on your requests
and receive partial information about your activities on the original website